This IP address has been reported a total of
13
times from
6 distinct
sources.
51.161.34.246 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 5
reports;
Korea (the Republic of)
with 4
reports;
Germany
with 3
reports.
The most common categories in these recent reports were:
Brute-Force
13
times;
SSH
9
times;
Hacking
5
times;
Exploited Host
5
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Observed two SSH sessions using test / 77hfr$Cd=Z$=sM! from SSH-2.0-Go. Activity focused on dropping ...
show moreObserved two SSH sessions using test / 77hfr$Cd=Z$=sM! from SSH-2.0-Go. Activity focused on dropping and persisting files in writable locations: cd /dev/shm, creating w.sh, and writing astats and kstats via cat > files. The host was checked with cat /proc/cpuinfo | grep processor | wc -l and ps -eo pid,pcpu,comm --sort=-pcpu | head -n 10, plus process checks for astats and kstats. Persistence was attempted by reading crontab and adding an @reboot entry pointing to /dev/shm/w.sh with arguments including astats and netai. Cleanup/anti-forensics commands removed shell history and log files: .bash_history, utmp, wtmp, lastlog, yum.log, secure, and related paths. No downloads, port forwards, lateral movement, or hashes were observed.
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted to ...
show more[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted to log in to our emulated SSH service, then obtained shell access and executed commands, and finally delivered an executable payload.
Observed: 2026-10-05 16:37 UTC | 1 session | 27 events | SSH (port 22)
Attack chain:
1. 1 credential attempt: ubuntu/123456
2. Shell access obtained; 8 distinct commands executed: cd /dev/shm || cd /tmp || cd /var/run || cd /mnt || cd /root ; uname -a ; sh -c 'for d in /dev/shm /tmp /var/run /mnt /root /; do cd "
3. Malicious script dropped: SHA-256 bc36e729c6463e7120677c0d59b9d793401b320520201043048577d4d94cee28, 1,421 bytes, script (#!/usr/bin/env bash)
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/10/51.161.34.246.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
Observed 2 SSH sessions from SSH-2.0-Go using root/M$uX_8z3D_m-AI=. Activity was focused on host dis ...
show moreObserved 2 SSH sessions from SSH-2.0-Go using root/M$uX_8z3D_m-AI=. Activity was focused on host discovery and persistence setup. Commands ran uname -a, cpu count via /proc/cpuinfo, and ps -eo pid,pcpu,comm --sort=-pcpu | head -n 10. The actor checked writable locations with sh -c 'for d in /dev/shm /tmp /var/run /mnt /root /; do cd "$d" 2>/dev/null && pwd && break; done'. Persistence steps targeted /tmp/w.sh: cd "/tmp" && if [ ! -f "w.sh" ]; then cat > "w.sh" && chmod +x w.sh; fi, then crontab was read and modified to add an @reboot entry referencing /tmp/w.sh with strings including astats, netai, kstats, and "ssh 2 az". No downloads, payload execution, lateral movement, or artifacts were observed in the session.
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
Oct 3 22:53:35 gibson-app sshd[2641160]: Invalid user pi from 51.161.34.246 port 40238
Oct 3 22:53 ...
show moreOct 3 22:53:35 gibson-app sshd[2641160]: Invalid user pi from 51.161.34.246 port 40238
Oct 3 22:53:35 gibson-app sshd[2641162]: Invalid user oracle from 51.161.34.246 port 40254
Oct 3 22:53:35 gibson-app sshd[2641164]: Invalid user steam from 51.161.34.246 port 40270
...
show less
Brute-Force
SSH
Showing 1 to
13
of 13 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ